CSSLP · Question #5
Which of the following roles is also known as the accreditor?
The correct answer is D. Designated Approving Authority. The Designated Approving Authority (DAA) is the senior official responsible for accepting the risk of operating an information system and formally granting the authorization to operate, effectively acting as the 'accreditor'.
Question
Which of the following roles is also known as the accreditor?
Options
- AData owner
- BChief Risk Officer
- CChief Information Officer
- DDesignated Approving Authority
How the community answered
(30 responses)- B7% (2)
- C3% (1)
- D90% (27)
Why each option
The Designated Approving Authority (DAA) is the senior official responsible for accepting the risk of operating an information system and formally granting the authorization to operate, effectively acting as the 'accreditor'.
A data owner is responsible for specific data assets, not the accreditation of an entire system.
A Chief Risk Officer (CRO) manages overall enterprise risk but typically does not serve as the accreditor for individual IT systems.
A Chief Information Officer (CIO) leads IT strategy and operations, but the specific authority for system accreditation usually rests with a DAA.
The Designated Approving Authority (DAA) is the management official who formally accepts the risk associated with operating an information system and grants the Authorization to Operate (ATO), which is the formal accreditation. This role is pivotal in risk management frameworks, signifying executive acceptance of residual security risks.
Concept tested: Designated Approving Authority (DAA) role
Source: https://csrc.nist.gov/glossary/term/designated-approving-authority
Topics
Community Discussion
No community discussion yet for this question.